Logfile of HijackThis v1.99.1
Scan saved at 5:39:53 PM, on 4/21/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\NORTON~2\NORTON~1\navapw32.exe
C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\slserv.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
C:\Program Files\aim\aim.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Kelly Ann\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.emachines.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.emachines.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {00866407-7AF6-4F56-AC13-912369171802} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {03A22CEA-3DB1-4579-9D29-EBFA6BC21D38} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {0F7C54D4-E207-4529-B1A8-3A031B8FB139} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {1FE9718F-2B52-4416-8E1B-DF577664247B} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {34EDC760-5BE6-4DEB-AC31-5E48B89E8898} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {417A3ED0-C591-4969-B802-8B2748185A31} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {74E2FF96-BFD0-48D1-8484-0D494AF7E642} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {78424CFB-E307-497C-9E52-0CCCDC133D79} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {92DB813F-BAAA-44E6-B3E4-B3D1AE5AADCF} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {A117728D-FA0C-4AB6-A07A-1E8F219E99BE} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {A78860C8-EE1A-46DF-A97F-E3E6D433E80B} - C:\WINDOWS\system32\alf3xv.dll
O2 - BHO: (no name) - {B239699B-9CB1-42DA-BC3C-FDBBACCD348E} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {BD88D2B2-963F-4F42-BF85-2A32B47CBDEC} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {CF74ABB9-1174-47BC-A467-589C5161AD43} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {D0597ECB-9ECF-48EC-A73F-8FBD10F2D16D} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {D976C6AF-41DB-43DC-851B-6FA2C4CE6F2B} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O2 - BHO: (no name) - {E73AC1EC-65D2-437C-8701-3370C6C1B5A8} - C:\Program Files\w5gtgl27\w5gtgl27.dll
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~2\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [hshnin] C:\DOCUME~1\KELLYA~1\LOCALS~1\Temp\sgnpvql.exe
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitepdt32.exe
O4 - HKLM\..\Run: [Nsv] C:\WINDOWS\System32\nsvsvc\nsvsvc.exe
O4 - HKLM\..\RunOnce: [2dn1og.exe] C:\WINDOWS\System32\2dn1og.exe /k
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /STARTMONITOR
O4 - HKCU\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /0
O4 - HKCU\..\RunOnce: [2dn1og.exe] C:\WINDOWS\System32\2dn1og.exe /k
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O23 - Service: McAfee Firewall - Unknown owner - C:\Program Files\McAfee\McAfee Firewall\CPD.EXE" /SERVICE (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe